Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).

“The filename parameter is concatenated into

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Now we have a timeline of the OpenAI accidental attack against Hugging Face

Now we have a timeline of the OpenAI accidental attack against Hugging Face Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 21.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 34.175.103.230 — 523 requests (recent log) 89.167.35.212 — 392 requests (recent log) 216.244.66.232 — 118 requests (recent

Reparaible and open source paper printer

Reparaible and open source paper printer Source: Hacker News